2015 CVE Vulnerabilities
8,779 CVEs published in 2015.
| CVE ID | Severity | CVSS | EPSS | Published | Description |
|---|---|---|---|---|---|
| CVE-2015-1465 | — | — | 6.5% | Apr 5, 2015 | The IPv4 implementation in the Linux kernel before 3.18.8 does not properly consider the length of the Read-Copy Update ... |
| CVE-2015-0777 | — | — | 0.4% | Apr 5, 2015 | drivers/xen/usbback/usbback.c in linux-2.6.18-xen-3.4.0 (aka the Xen 3.4.x support patches for the Linux kernel 2.6.18),... |
| CVE-2015-0951 | — | — | 1.3% | Apr 5, 2015 | X-Cart before 5.1.11 allows remote authenticated users to read or delete address data of arbitrary accounts via a modifi... |
| CVE-2015-0950 | — | — | 1.2% | Apr 5, 2015 | Cross-site scripting (XSS) vulnerability in admin.php in X-Cart 5.1.6 through 5.1.10 allows remote attackers to inject a... |
| CVE-2015-0932 | — | — | 5.6% | Apr 5, 2015 | The ANTlabs InnGate firmware on IG 3100, IG 3101, InnGate 3.00 E, InnGate 3.01 E, InnGate 3.02 E, InnGate 3.10 E, InnGat... |
| CVE-2015-0529 | — | — | 2.9% | Apr 5, 2015 | EMC PowerPath Virtual Appliance (aka vApp) before 2.0 has default passwords for the (1) emcupdate and (2) svcuser accoun... |
| CVE-2015-2111 | — | — | 0.5% | Apr 4, 2015 | Unspecified vulnerability in HP Intelligent Provisioning 1.40 through 1.60 on Windows Server 2008 R2 and 2012 allows loc... |
| CVE-2015-0688 | — | — | 1.7% | Apr 4, 2015 | Cisco IOS XE 3.10.2S on an ASR 1000 device with an Embedded Services Processor (ESP) module, when NAT is enabled, allows... |
| CVE-2015-0616 | — | — | 1.7% | Apr 3, 2015 | The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6... |
| CVE-2015-0615 | — | — | 1.7% | Apr 3, 2015 | The call-handling implementation in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6(2a)SU4, 9.x before 9.1(2... |
| CVE-2015-0614 | — | — | 1.7% | Apr 3, 2015 | The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6... |
| CVE-2015-0613 | — | — | 1.7% | Apr 3, 2015 | The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU7, 8.6 before 8.6... |
| CVE-2015-0612 | — | — | 1.7% | Apr 3, 2015 | The Connection Conversation Manager (aka CuCsMgr) process in Cisco Unity Connection 8.5 before 8.5(1)SU6, 8.6 before 8.6... |
| CVE-2015-2841 | — | — | 5.5% | Apr 3, 2015 | Citrix NetScaler AppFirewall, as used in NetScaler 10.5, allows remote attackers to bypass intended firewall restriction... |
| CVE-2015-2840 | — | — | 2.0% | Apr 3, 2015 | Cross-site scripting (XSS) vulnerability in help/rt/large_search.html in Citrix NetScaler before 10.5 build 52.3nc allow... |
| CVE-2015-2839 | — | — | 2.0% | Apr 3, 2015 | The Nitro API in Citrix NetScaler before 10.5 build 52.3nc uses an incorrect Content-Type when returning an error messag... |
| CVE-2015-2838 | — | — | 2.9% | Apr 3, 2015 | Cross-site request forgery (CSRF) vulnerability in Nitro API in Citrix NetScaler before 10.5 build 52.3nc allows remote ... |
| CVE-2015-0225 | — | — | 6.7% | Apr 3, 2015 | The default configuration in Apache Cassandra 1.2.0 through 1.2.19, 2.0.0 through 2.0.13, and 2.1.0 through 2.1.3 binds ... |
| CVE-2015-0995 | — | — | 1.1% | Apr 3, 2015 | Inductive Automation Ignition 7.7.2 uses MD5 password hashes, which makes it easier for context-dependent attackers to o... |
| CVE-2015-0994 | — | — | 1.3% | Apr 3, 2015 | Inductive Automation Ignition 7.7.2 allows remote authenticated users to bypass a brute-force protection mechanism by us... |
| CVE-2015-0993 | — | — | 2.3% | Apr 3, 2015 | Inductive Automation Ignition 7.7.2 does not terminate a session upon a logout action, which allows remote attackers to ... |
| CVE-2015-0992 | — | — | 0.3% | Apr 3, 2015 | Inductive Automation Ignition 7.7.2 stores cleartext OPC Server credentials, which allows local users to obtain sensitiv... |
| CVE-2015-0991 | — | — | 1.4% | Apr 3, 2015 | Inductive Automation Ignition 7.7.2 allows remote attackers to obtain sensitive information by reading an error message ... |
| CVE-2015-0990 | — | — | 0.4% | Apr 3, 2015 | Untrusted search path vulnerability in Ecava IntegraXor SCADA Server before 4.2.4488 allows local users to gain privileg... |
| CVE-2015-0976 | — | — | 1.1% | Apr 3, 2015 | Cross-site scripting (XSS) vulnerability in Inductive Automation Ignition 7.7.2 allows remote attackers to inject arbitr... |
Check if your code is affected by 2015 CVEs
Strix scans your code and infrastructure for known vulnerabilities automatically.
Scan your code now